Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25873
HistoryJul 13, 2020 - 6:03 a.m.

Information Disclosure

2020-07-1306:03:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

EPSS

0.008

Percentile

81.2%

jetty-server is vulnerable to information disclosure. An HTTP 431 error occurs when large response headers are received, causing the HTTP response headers to be released to ByteBufferPool twice. This results in a double release and memory corruption and causes confidential information to be disclosed.

References